On this page
- Plain-language summary
- Account information you provide
- Information about your child
- Milestone observations
- Location data
- How we use this information
- Sharing with third parties
- Third-party services we use
- Data retention
- Your rights and choices
- Children's privacy
- Security
- Changes to this policy
- Contact
1. Plain-language summary
If you're short on time, here's the gist:
- We collect what we need to run the app — your email, your password (hashed), your child's date of birth and basic developmental context, and the milestones you log.
- We do not sell your data, share it with advertisers, or use it for advertising profiling.
- We do not track you with third-party analytics, fingerprinting libraries, or social-media SDKs.
- We do not use your child's milestone data to train any machine-learning model.
- You can delete your account and all associated data at any time by emailing us.
- Tendling is a wellness companion, not a medical device, and is intended for use by parents and guardians of children under 18.
2. Account information you provide
When you create a Tendling account, we collect:
- Email address — used as your unique account identifier and for occasional account-related communication (password reset, security notice). Not used for marketing.
- Display name (optional) — shown in the app's greeting.
- Password — stored only as a salted hash using a modern algorithm (PBKDF2). We cannot recover your password; if you forget it, you'll need to reset it.
3. Information about your child
For each child you add to your account, you may provide:
- First name or initials — for display only; you can use just an initial if you prefer.
- Date of birth — required, used for chronological-age calculation.
- Sex at birth — used to display "girl" / "boy" / "child" in the interface.
- Gestational age at birth and NICU days (optional) — used to compute corrected age for preterm babies. Defaults to full-term values if not provided.
- Birth weight, multiple-birth flag, birth order (all optional) — context fields not currently used for any algorithmic decision.
This information is associated only with your account and is visible only to you.
4. Milestone observations
When you log a milestone for your child, we store:
- Which milestone (referenced from the public CDC catalog)
- The status you marked: Observed, Emerging, or Not yet
- The date you observed it (optional)
- An optional note you may add
- The timestamp of when you logged it
Your observations are private to your account.
5. Location data
The "Find specialists nearby" feature lets you search for pediatric providers in your area. In the current version of Tendling, you choose a search city manually — the app does not request your device's precise location.
If a future version adds device-location support, it will use Apple's standard "When in Use" permission flow, will be opt-in, and your location will be used only to compute the search query (it is not stored on our servers).
6. How we use this information
We use the data above only to:
- Provide the app's core function: tracking milestones, computing corrected age, surfacing CDC act-early indicators, displaying summaries, and finding nearby specialists when you ask.
- Authenticate you across sessions.
- Diagnose technical problems and improve reliability (server logs of HTTP requests; logs are rotated and contain no observation content).
- Communicate about your account when needed (e.g. security notice).
We do not use your data for behavioral profiling, advertising, model training, or sale to third parties.
7. Sharing with third parties
We do not sell, rent, or share your personal information with third parties for advertising or marketing purposes. We share information only in these limited cases:
- When you choose to share — for example, the in-app "Share with pediatrician" feature generates an image you can send via email, AirDrop, or any sharing destination on your device. What you share, when, and with whom is entirely your decision.
- Service providers — we use a small number of vendors to operate the service (see "Third-party services" below). They process data on our behalf under standard data-processing agreements.
- Legal requirements — we may disclose information if required by valid legal process (subpoena, court order). We will notify the affected user unless legally prohibited.
8. Third-party services we use
Tendling is built on the following infrastructure and data sources:
- DigitalOcean — hosts the application server and database in a US data center (New York). Your account and child data live here.
- U.S. Census Geocoding Service — used during a one-time ingestion of provider addresses to compute coordinates for the "Find help" feature. Your personal data is never sent to Census.
- NPPES (CMS National Plan and Provider Enumeration System) — public US government dataset of healthcare providers; used to populate the "Find help" provider directory. Your personal data is never sent to NPPES.
- Let's Encrypt — issues the TLS certificate that secures connections to
tendling.org. - Apple App Store / TestFlight — distribution and beta-testing of the iOS app. Apple's own privacy practices govern crash reporting opt-ins and Apple ID handling.
We do not use Google Analytics, Facebook SDK, advertising trackers, or third-party crash reporters.
9. Data retention
We keep your account data as long as your account is active. If you delete your account, we delete your account record, child records, and observation history within 30 days. Aggregated, non-identifying log data may be retained longer for security and operational purposes.
10. Your rights and choices
You have the right to:
- Access — request a copy of the data we hold about you and your children.
- Correct — fix inaccuracies (most fields are editable directly in the app).
- Delete — delete individual children, observations, or your entire account.
- Export — request your data in a portable format (we provide JSON export on request).
- Withdraw consent — stop using the app and delete your account at any time.
To exercise any of these rights, email hello@tendling.org from the address associated with your account. We respond within 30 days.
California residents (CCPA), Virginia residents (VCDPA), and residents of other US states with comprehensive privacy laws have the same rights described above; the legal terminology may differ but the practical effect is the same.
11. Children's privacy
Tendling is intended for use by parents and legal guardians. The data you log relates to your minor child(ren), but you (the parent) are the account holder, and Tendling is not directed to children under 13 as users.
We collect only the minimum data about your child needed for the app's purpose. We never use that data to advertise to your child, profile them, or share with third parties for their own purposes.
Tendling complies with the Children's Online Privacy Protection Act (COPPA) by limiting data collection about minors to what a parent voluntarily provides about their own child for the parent's own use. If you believe a child has independently created an account on Tendling, please contact us and we'll remove it.
12. Security
We use standard industry practices to protect your data:
- HTTPS everywhere (TLS 1.2+) for data in transit.
- Passwords hashed with PBKDF2 — we cannot recover them.
- Authentication tokens (JWT) issued with short-lived access windows and refreshable.
- Database access restricted to the application server; not exposed to the public internet.
- Server access by the operator is via SSH key authentication only.
No system is perfectly secure. If we ever experience a data incident affecting your information, we'll notify you promptly with what happened and what steps you can take.
13. Changes to this policy
We may update this policy from time to time. If we make material changes, we'll update the "Last updated" date at the top and notify users by email at the address on file. Continuing to use Tendling after a change constitutes acceptance of the updated policy.
14. Contact
Questions, requests, or concerns about this policy or your data:
Email: hello@tendling.org
We aim to respond within 5 business days.